BREACH WATCH BRIEF High 👤 Threat intel

Thousands of Wind & Solar Park Systems Exposed on the Open Internet Across Europe

Researchers uncovered 8,547 internet‑facing wind‑farm and solar‑park control systems across 35 EU countries, many with unsecured login pages and turbine‑control dashboards. The finding highlights gaps in network segmentation and remote‑access controls that must be documented for audit readiness.

SeverityHigh
Type👤 Threat intel
ConfidenceHigh
ReportedOct 9, 2026
Energy & Utilities Renewable‑energy operators (wind and solar) OT device vendors and managed‑service providers Misconfiguration

What happened

Modat and the Dutch NCSC identified 8,547 publicly reachable OT devices at wind farms and solar parks in 35 European nations. Exposed interfaces include login screens, turbine control panels with start/stop buttons, and PLC web servers, some using default root credentials.

Why it matters for trust and compliance

  • The exposure tests the control objective of network segmentation and remote‑access restrictions, a cornerstone of continuous control‑assurance and audit evidence across frameworks.
  • Demonstrates the need for continuous evidence that OT assets are isolated from public networks.
  • Provides a basis for mapping remediation steps to control objectives required by multiple compliance frameworks.

Who is affected

Renewable‑energy operators (wind and solar) OT device vendors and managed‑service providers

Recommended actions

  1. Inventory all OT assets and tag any internet‑exposed endpoints.
  2. Implement strict network segmentation and enforce VPN or jump‑host access for control systems.
  3. Deploy continuous monitoring to detect new internet‑facing OT assets and generate audit‑ready evidence.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.